SUSPICIOUS — fizovamezoguvijofuk.pdf
SUSPICIOUS — fizovamezoguvijofuk.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
dd47d2827f62540518f3ca71de7783225f1d82d1686b9093cf3fdce4999cf296 - SHA-1:
51d0596d293de6c52caf11bd5198b7ccc3763a8e - MD5:
77cab5b1af22ed9eec23f8bd6abb3ef4 - ssdeep:
768:1gGzpDMe1QGpNd79po/8TSE/WbEKVYzb1brKrGi7wOl8f7yG36A:mGFQe/Y/8TSSMKzsrGiMOlwP36A - TLSH:
T10D348DF34057ED8C77CAAB07AAAB115C508EE78E7137A790058C762DD57CABD6E00A10 - Submitted as: fizovamezoguvijofuk.pdf
- File type: pdf · Size: 55255 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20republic%20plato, https://site-1043447.mozfiles.com/files/1043447/81385670221.pdf, https://site-1036814.mozfiles.com/files/1036814/90452685597.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20republic%20plato
- https://site-1043447.mozfiles.com/files/1043447/81385670221.pdf
- https://site-1036814.mozfiles.com/files/1036814/90452685597.pdf
- https://site-1041770.mozfiles.com/files/1041770/95107259797.pdf
- https://uploads.strikinglycdn.com/files/1b0d0867-6f9c-4f25-8c00-454f0b7f4591/kanelesupuluvaxafiriz.pdf
- https://uploads.strikinglycdn.com/files/d9541759-b1c7-4732-95a8-35f6ab49b07c/6392050863.pdf
- https://uploads.strikinglycdn.com/files/de76fe20-4c38-406a-8322-3f095db02209/82135781822.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f871e52874f2.pdf
- https://cdn-cms.f-static.net/uploads/4369306/normal_5f8880371ce64.pdf
- https://site-1037860.mozfiles.com/files/1037860/sorejenanowivexilex.pdf
- https://site-1039330.mozfiles.com/files/1039330/rafozarozexibulopegum.pdf
- https://uploads.strikinglycdn.com/files/c5d02b0e-728d-4264-a202-b4630b6ccfc7/kilapopojewuzudazabodus.pdf
- https://uploads.strikinglycdn.com/files/0257aa80-5f63-4b8e-af5f-ce470a31eee0/radij.pdf
- https://uploads.strikinglycdn.com/files/87cec736-28fe-43ed-bd8c-24d5b08e72a8/13207972352.pdf
- https://uploads.strikinglycdn.com/files/442f200e-ceff-4a31-a059-0ecdf238869a/61321770813.pdf
- https://uploads.strikinglycdn.com/files/655e1d1e-7e81-4740-b209-09015a2b76a6/vevefin.pdf
- https://cdn.shopify.com/s/files/1/0430/8120/3861/files/69697044035.pdf
- https://cdn.shopify.com/s/files/1/0429/1290/7423/files/90223543148.pdf
- https://cdn.shopify.com/s/files/1/0428/1624/1831/files/7085536036.pdf
- https://cdn.shopify.com/s/files/1/0268/8037/7028/files/ridapajulubetatodug.pdf
- https://cdn.shopify.com/s/files/1/0430/4925/5061/files/how_long_does_a_direct_deposit_take_to_go_through.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1043447.mozfiles.com
- site-1036814.mozfiles.com
- site-1041770.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1037860.mozfiles.com
- site-1039330.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report